CVE-2019-11972: SQL Injection
Published Jun 5, 2019
·Updated
A SQL injection code execution vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.
Affected Software
9 affected components
HP Intelligent Management Center<7.3
HP Intelligent Management Center=7.3
HP Intelligent Management Center=7.3-e0503
HP Intelligent Management Center=7.3-e0504
HP Intelligent Management Center=7.3-e0504p02
HP Intelligent Management Center=7.3-e0504p04
HP Intelligent Management Center=7.3-e0506
HP Intelligent Management Center=7.3-e0506p03
HP Intelligent Management Center=7.3-e0506p07
Event History
Jun 5, 2019
CVE Published
via MITRE·03:24 PM
Data Sourced
via MITRE·03:24 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2019-11972?
CVE-2019-11972 has a high severity rating due to its potential to allow SQL injection attacks.
2
How do I fix CVE-2019-11972?
To mitigate CVE-2019-11972, it is recommended to upgrade to a version of HPE Intelligent Management Center later than 7.3 E0506P09.
3
Which versions of HPE Intelligent Management Center are affected by CVE-2019-11972?
HPE Intelligent Management Center versions earlier than 7.3 E0506P09 are affected by CVE-2019-11972.
4
What type of vulnerability is CVE-2019-11972?
CVE-2019-11972 is a SQL injection vulnerability that can lead to code execution.
5
Can CVE-2019-11972 be exploited remotely?
Yes, CVE-2019-11972 can potentially be exploited remotely by an attacker.